
🚨Critical - YesWiki Unauthenticated Arbitrary Page Deletion (CVE-2026-52766) YesWiki's {{erasespamedcomments}} action takes a suppr[] array from POST and deletes every wiki page whose tag appears in it, with no authorization, ownership, or CSRF check. YesWiki's allow-by-default ACL model (default_write_acl='*' on a fresh install) means even anonymous users can invoke it, and the deleteOrphaned() callee - despite its name - issues unconditional DELETEs across pages, links, acls, triples, referrers, and tags. An unauthenticated attacker can create a trigger page, then POST clean=yes&suppr[]=... to permanently delete arbitrary pages, including the front page and admin pages. High integrity and availability impact. 👉Upgrade YesWiki to 4.6.6.
Post summary
YesWiki's default ACL model allows unauthenticated arbitrary page deletion via a POST suppr[] array; upgrading to version 4.6.6 mitigates the issue.
